PT-2019-12159 · Sunnet · Sunnet Wmpro

·

CVE-2019-11062

·

Published

2019-07-11

·

Updated

2023-03-01

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions SUNNET WMPro versions 5.0 through 5.1
Description The issue concerns an OS Command Injection vulnerability. It can be exploited via the "/teach/course/doajaxfileupload.php" API endpoint without requiring authentication.
Recommendations For versions 5.0 and 5.1, consider restricting access to the "/teach/course/doajaxfileupload.php" API endpoint until a patch is available. As a temporary workaround, disabling the functionality related to this endpoint may help minimize the risk of exploitation.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-11062

Affected Products

Sunnet Wmpro